CVE-2005-4807
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
31/12/2005
Last modified:
03/04/2025
Description
Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute arbitrary code via a .c file with crafted inline assembly code.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:* | 2.17 (excluding) | |
cpe:2.3:o:canonical:ubuntu_linux:5.04:*:*:*:*:*:*:* | ||
cpe:2.3:o:canonical:ubuntu_linux:5.10:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://bugs.gentoo.org/show_bug.cgi?id=99464
- http://secunia.com/advisories/21508
- http://secunia.com/advisories/21530
- http://www.osvdb.org/27960
- http://www.securityfocus.com/bid/19555
- http://www.ubuntu.com/usn/usn-336-1
- http://www.vupen.com/english/advisories/2006/3307
- http://bugs.gentoo.org/show_bug.cgi?id=99464
- http://secunia.com/advisories/21508
- http://secunia.com/advisories/21530
- http://www.osvdb.org/27960
- http://www.securityfocus.com/bid/19555
- http://www.ubuntu.com/usn/usn-336-1
- http://www.vupen.com/english/advisories/2006/3307